CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5036  CVE-2002-0646  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0371. Reason: This candidate is a reservation duplicate of CVE-2002-0371. Notes: CVE-2002-0371 should be used instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20020628)  NOOP(1) Christey  Christey> DO NOT USE THIS CANDIDATE. | It is a "reservation duplicate" of CVE-2002-0371. CVE users | should use CVE-2002-0371 instead.  View
5037  CVE-2002-0647  Entry  Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".        View
5038  CVE-2002-0648  Entry  The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.        View
5039  CVE-2002-0649  Candidate  Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.  Modified (20080207)  ACCEPT(4) Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Christey> CERT:CA-2002-22 | CERT-VN:VU#399260 | CERT-VN:VU#484891 | Christey> XF:mssql-resolution-service-bo(9661) | URL:http://www.iss.net/security_center/static/9661.php | BID:5310 | URL:http://www.securityfocus.com/bid/5310 | BID:5311 | URL:http://www.securityfocus.com/bid/5311 | Christey> add to desc: "as exploited by the SQL Slammer/Sapphire worm" | to facilitate matching. | Frech> XF:mssql-resolution-service-bo(9661)  View
5040  CVE-2002-0650  Entry  The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.        View

Page 1008 of 20943, showing 5 records out of 104715 total, starting on record 5036, ending on 5040

Actions